PE Packers Used in Malicious Software [PPT]

Hackers commonly compile custom backdoors and applications to use on a compromised host. These custom applications can contain sensitive information about the attacker himself, even his own IP address. Disassembly of the trojan binary would reveal this information easily, but when the executable is PE packed, what path do you next take?

This presentation aims to debunk the PE packing myth, showing just how easy unpacking a PE packed binary can be.




Post new comment

  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <h1> <quote> <img>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.